PT-2004-3049 · Apple+1 · Cups+1
Published
2004-12-31
·
Updated
2024-08-01
·
CVE-2004-2154
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CUPS versions prior to 1.1.21rc1
Description
The issue allows attackers to bypass intended Access Control Lists (ACLs) due to the case-sensitive treatment of a Location directive in cupsd.conf. This can be exploited via a printer name containing uppercase or lowercase letters that differ from what is specified in the directive.
Recommendations
For versions prior to 1.1.21rc1, update to version 1.1.21rc1 or later to resolve the issue. As a temporary workaround, consider ensuring that all printer names and Location directives in cupsd.conf are specified with consistent case to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cups
Red Hat